CVE-2017-1480: Medium severity IBM Security Access Manager vulnerability
Published Jun 6, 2018
·Updated
IBM Security Access Manager Appliance 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 stores potentially sensitive information in log files that could be read by a remote user. IBM X-Force ID: 128617.
Affected Software
3 affected components
IBM Security Access Manager>=9.0.0<=9.0.3.1
IBM Security Access Manager for Web>=8.0.0<=8.0.1.6
IBM Security Access Manager for Mobile>=8.0.0<=8.0.1.6
Remediation
Patch Available
Event History
Jun 6, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2017-1480.
2
What is the severity of CVE-2017-1480?
The severity of CVE-2017-1480 is medium (4.3).
3
Which software versions are affected by CVE-2017-1480?
IBM Security Access Manager Appliance versions 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 are affected.
4
What is the potential impact of CVE-2017-1480?
CVE-2017-1480 allows a remote user to read potentially sensitive information stored in log files.
5
Are there any known fixes or mitigations for CVE-2017-1480?
Yes, IBM has provided fixes for the affected versions of IBM Security Access Manager Appliance. Please refer to the IBM support documentation for specific details.